Back

HIGH

FFmpeg IAMF Demuxer Uncontrolled Resource Consumption via mix_presentation_obu()

Published Jul 24, 2026

Description

FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The mix_presentation_obu() function in libavformat/iamf_parse.c calls av_calloc(count_label, sizeof(*language_label)) with an attacker-controlled value before validating available OBU data, enabling an allocation amplification of approximately 126 million bytes per input byte that exhausts process memory or triggers an OOM-kill during format probing.

Affected products

Remediation

No remediation recorded yet.

References (8)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner VulnCheck
Published Jul 24, 2026
Updated Jul 28, 2026
Reserved Jul 23, 2026

CISA Vulnrichment

Updated Jul 27, 2026

NVD

Status Analyzed
Modified Aug 7, 2026

Red Hat

Severity Moderate
Public date Jul 24, 2026
Bugzilla 2506911

ENISA EUVD

Assigner VulnCheck
Published Jul 24, 2026
Updated Jul 28, 2026

GitHub

No data